CVE 4.3 MEDIUM

WordPress core <= 6.8.2 - (Contributor+) Sensitive Data Exposure vulnerability_CVE-2025-58246

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data.

The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it.
This issue affects WordPress: from n/a through 6.8.2

Basic Information

ID CVE-2025-58246
Source Patchstack
Published Sep 23, 2025 at 17:17

Affected Product

Vendor Automattic
Product WordPress
Version n/a
Affected Versions Automattic WordPress n/a

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.